Data Processing Addendum
Overview
This page sets out the terms of the PentestOps Data Processing Addendum (DPA), including our roles, sub-processors, international transfers, security measures, breach notification, audit rights, and return and deletion of data. The DPA governs how Extranet Systems Pty Ltd processes personal data on behalf of our customers when they use PentestOps, and supplements our Terms of Service and Privacy Policy.
Requesting the DPA
A signable DPA is available to customers on request. Please email privacy@pentestops.ai or legal@pentestops.ai and we will provide the current version for execution.
Controller and processor roles
For personal data you submit to PentestOps, the roles are as follows:
- You (the customer) act as the data controller. You decide what data is processed and for what purpose, and you are responsible for having a lawful basis and the necessary authorisation to scan your targets.
- Extranet Systems acts as the data processor. We process personal data only on your documented instructions to provide and support the service.
We process data for the limited purposes of delivering security testing, generating reports, and supporting your account, and we apply the technical and organisational measures described in our Trust Centre.
Sub-processors
We engage a small number of vetted sub-processors to deliver the service, each bound by contract to protect personal data. Our current sub-processors and their purposes are listed in our Trust Centre. We will give customers notice of material changes so they can raise any reasonable objection.
International data transfers
Where personal data is transferred outside its country of origin, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), to provide a lawful basis for the transfer. Region details and data-residency options for Enterprise customers are described in our Trust Centre.
Security measures
We implement and maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include:
- Encryption. Customer data is encrypted at rest, and all traffic is protected with TLS in transit.
- Tenant isolation. Every customer runs in an isolated Kubernetes namespace with its own dedicated database. There is no shared tenant data store.
- Access control. Role-based access control, with multi-factor authentication available on every account and required for administrators.
- Secrets management. Credentials and signing keys are held in a dedicated secrets vault and injected at runtime, never committed to source.
- Logging. A tamper-evident audit log is retained for 365 days.
- Certification. Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. A copy of the certificate is available on request.
The current measures are described in more detail in our Trust Centre. We may update them over time provided the overall level of protection is not reduced.
Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, so that you can meet your own regulatory notification obligations as controller.
Our notification will, to the extent known at the time, describe:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address it and to mitigate its effects; and
- a contact point for further information.
Where the full picture is not available immediately, we will provide information in phases as the investigation progresses rather than delaying the initial notification. We will also reasonably assist you in meeting your obligations to notify supervisory authorities and affected individuals.
Audit rights
We will make available the information reasonably necessary to demonstrate our compliance with our obligations as processor, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
- Documentation first. In most cases our ISO/IEC 27001:2022 certification and supporting documentation will satisfy an audit request, and we will provide these on request.
- On-request audits. Where that is not sufficient for your regulatory obligations, audits may be carried out on reasonable prior written notice, during business hours, no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach.
- Scope limits. Audits must not compromise the security, confidentiality or availability of other customers' data, and the auditor must be bound by appropriate confidentiality obligations.
Return and deletion of data
Assessment findings and scan data are retained according to your plan, then deleted automatically:
- Starter: 1 year
- Professional: 3 years
- Enterprise and MSP: up to 7 years, with custom retention available
On termination or expiry of your subscription, we will delete or return personal data processed on your behalf at your choice, except where we are required by law to retain it. Exported reports, signed authorisation records and legal documents are kept as records of the engagement and are not removed by the routine retention process. Findings can be placed on legal hold where you need them preserved.
Details of processing
- Subject matter and duration. Provision of the PentestOps platform for the term of your subscription, plus the retention period above.
- Nature and purpose. Security testing, vulnerability and exposure management, exploit validation, remediation guidance and reporting.
- Types of personal data. Account and contact details of your authorised users; and any personal data incidentally present in scan targets, findings or evidence generated during testing of your systems.
- Categories of data subjects. Your personnel and authorised users, and any individuals whose data appears incidentally in the systems you authorise us to test.
- Assistance. Taking into account the nature of the processing, we will assist you with data subject requests and with your obligations on security, breach notification and data protection impact assessments.
We process personal data only on your documented instructions, and personnel authorised to access it are bound by confidentiality obligations.
Contact
For DPA requests, sub-processor questions, or data-protection enquiries, please contact us:
Extranet Systems Pty Ltd - Privacy & Legal
Privacy: privacy@pentestops.ai
Legal: legal@pentestops.ai
Trust Centre: pentestops.com/security